When someone proposes using AI for a specific task, the idea may be easy to describe and still be difficult to decide. If no one can answer what the AI will be used for, what needs to be in place, and who will make the decision, the next step remains unclear.
This does not require the company to complete a major AI programme first. But it does need a practical way to get every proposal to one of three outcomes: a yes, a no or an escalation. Without one, the same proposal can be passed between several functions without reaching a clear decision.
This is where AI governance can feel slow. Not because an assessment is itself a problem, but because the process for handling the proposal has not been made clear. This article is not about who has overall ownership of AI in the organisational chart. It is about how a specific proposal to use AI reaches a decision.
A decision needs a clear endpoint
It is entirely reasonable for different disciplines to have something to contribute. Security may have questions about data. Legal may have questions about the boundaries. Procurement may need to examine the supplier. The business may need to know whether the proposal can move forward.
But participation is not the same as making a decision. If a proposal must pass through several functions without agreement on who brings the assessments together and makes the next decision, every assessment may be relevant while the proposal still has no way forward.
A policy can describe what the company wants. It cannot, by itself, tell you what should happen to the next specific proposal. The same applies to a committee. It may be the right place for some proposals, but it does not answer where every proposal should begin or end.
The aim is therefore not to remove assessments. It is to make clear when they are needed, what they need to answer, and who takes the proposal forward afterwards.
NIST's AI Risk Management Framework is voluntary guidance, not a ready-made recipe for Danish companies. Among other things, the framework points to documented roles, responsibilities and lines of communication in work on AI risks. That is a useful principle here: the person raising a proposal should be able to see where it goes and what needs to happen before a decision is made.
Three questions before the proposal moves forward
A simple decision path can begin with three practical questions. They are not about creating a new title or building a heavy system. They are about the proposal on the table now.
What will the AI be used for?
Start by describing the proposal specifically enough that others can assess it. What will the AI tool be used for? Who will use it? What information is involved? And how will the result be used in the work?
There is no need to begin with a technical dissertation on model selection. What matters is the practical use. An internal aid for drafting text does not necessarily raise the same questions as an AI use involving customer data or affecting a decision about people.
A clear description does not make a proposal harmless. It makes it possible to see what review it needs. Without that description, the discussion can easily become about technology in general while no one decides on the specific proposal.
What needs to be in place?
The next question is not how many people need to be involved. It is what needs to be in place before a sound decision can be made.
In some cases, this may be a simple clarification of which information may be used. In others, there may be a need to assess the supplier, the specific use of AI, or the way the result will be used. The key is to make the requirements for the specific proposal clear, so that an assessment does not become an open-ended task with no endpoint.
It can be useful to work with different tracks, for example low, medium and high risk. This is not a legal classification. It is a practical way to determine what preparation and review a proposal requires. The organisation needs to be able to explain why two proposals are handled differently.
Where and when will the decision be made?
A proposal needs a clear endpoint and an expectation of when the decision will be made. This does not mean that every decision must be made quickly, or by the same person.
A simpler proposal may be decided closer to the work it concerns. A proposal with greater exposure may require a different decision-maker or a clear escalation. The key is that it is clear where the proposal goes once the necessary basis is in place.
Without an expectation of when a proposal will be decided, it is difficult to plan the work, and an otherwise clear process can still feel like a dead end. The company must determine a reasonable pace for its different tracks. There is no single deadline that suits every situation.
The three questions are connected. A proposal can be well described and still stall if no one knows what needs to be in place. It can be thoroughly assessed and still lack a way forward if no one knows where and when the decision will be made. The decision path needs to bring the three together.
Start with the next proposal
It can be tempting to begin with a strategy, a new policy or a complete overview of every AI tool. That may also become necessary. But the first step can be more practical: take the next proposal to use AI that lacks a decision and use it to see how decisions are actually made in your organisation.
Write down briefly what the AI will be used for and in what context. Then agree on which assessments need to be in place. Finally, identify where the decision will be made and when there should be a decision or an escalation.
If one of the three steps is unclear, you have a concrete piece of work to address. Perhaps the proposal needs a better description. Perhaps it is unclear which assessments are necessary. Perhaps there is no clear route from assessment to decision. It is more useful to spot this in a real proposal than to try to predict every future way of using AI at once.
Nor is this an exercise in removing caution. On the contrary. A clear process can make it easier to spend time on the proposals that require more, without treating every other proposal as though it does.
The AI Act is context, not a manual
This article is deliberately not a guide to the AI Act. It does not cover rules, deadlines or authorities. The practical task also exists before the legal detail: the company must be able to make and explain its decisions about using AI.
If a proposal requires a legal assessment, the decision path should make clear when that assessment needs to be brought in and where the proposal goes afterwards. That is not the same as having the answer to every legal question. It is about making the next step clear.
This article has focused on the route for a specific proposal. In my talk at Computerworld's Cyber Security Summit 2026 - København on Thursday 27 August at 13:50 on Blå scene, I will look at the broader organisational question: who can approve what, and how quickly?
If you are at the conference and working on the same questions, please come by after the talk and say hello. I will be at the conference for the rest of the day.